
The storm passes. The power comes back. Staff returns to the office. Everything looks normal. Then, three weeks later, a hard drive that flooded but kept working finally dies — and takes critical data with it. Or someone notices the firewall hasn’t been logging since the day before the storm. Or the backup that "finished successfully" turns out to be corrupted.
Most post-hurricane IT damage isn’t visible on day one. The audit you run in the first 30 days is what catches it before it becomes a bigger problem.
Week 1: physical and immediate
- Inspect every server, switch, and UPS for water damage. Even devices that turned on may have hidden corrosion.
- Check UPS battery health. Power events shorten battery life; a UPS that ran for hours during the storm may need its battery replaced.
- Verify backups completed during and after the storm. If backups skipped any days, document why.
- Confirm all employees have current credentials and working access (passwords often get forgotten during chaos).
- Verify firewall, switches, and access points are all logging correctly.
Week 2: data integrity
- Run a test-restore from backup. This is the only way to know your backup actually works.
- Spot-check critical files. Do they open? Are they current?
- Check Microsoft 365 / Google Workspace sync status — devices that lost connectivity may have local copies that didn’t sync.
- Audit who accessed what during the chaos. Were any unauthorized logins attempted from unusual locations?
- Inventory any equipment that was off-site (employees taking laptops home, vendors with loaner gear). Account for everything.
Week 3: security posture
- Force a password reset for any account where the user changed device, network, or location during the storm.
- Review remote access logs. Were there sessions from unusual IPs or at unusual hours?
- Patch everything. Many devices skipped scheduled patching during the storm window.
- Verify MFA is still enforced — emergency exceptions made during the storm sometimes become permanent if no one cleans them up.
- If staff worked from personal devices, ensure no company data is sitting on those devices unencrypted.
Week 4: documentation and lessons learned
- Update the incident response plan based on what actually happened.
- Refresh the contact list (some vendors and staff may have new numbers).
- Document what worked. Document what didn’t.
- Schedule the next hurricane-readiness review (March/April is a good time for next year).
- If there were any data losses or near-misses, file the insurance documentation while details are fresh.
The hidden things that bite Houston businesses
Backup tape rotation that broke. If you still use tapes or external drives that rotate off-site, the chain of custody often breaks during storms. Some weeks of backup may be missing.
Cloud sync conflicts. When devices lose connectivity for days then come back, sync conflicts can quietly create duplicate or stale files.
SSL certificates and DNS. If you renewed during the storm window, verify everything actually completed.
Equipment that’s slowly failing. Hard drives that got wet but kept working often fail 30-90 days later. Plan replacements proactively.
If you don’t have time to run this yourself
Our managed clients get a post-storm audit included whenever a named storm impacts Houston. If you’re not on managed services and want one done, book a discovery call — we can run the audit as a one-off engagement.
Aspendora Technologies has been doing post-storm IT recovery for Houston-area small businesses since before Harvey. Managed IT, data backup and recovery, and cybersecurity from a La Porte base.
